CVE-2026-68502 | grisuno LazyOwn up to 0.2.153 Socket.IO Input Event lazyc2.py subprocess.call Value os command injection
A vulnerability was found in grisuno LazyOwn up to 0.2.153. It has been rated as critical. This vulnerability affects the function subprocess.call of the file lazyc2.py of the component Socket.IO Input Event Handler. This manipulation of the argument Value causes os command injection.
This vulnerability is tracked as CVE-2026-68502. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.VulDB Recent EntriesRead More